Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
What it requires →
The ADGM Data Protection Regulations set an explicit 72-hour breach-notification rule to the Commissioner of Data Protection, language read verbatim and drawn from the same family as General Data Protection Regulation (GDPR) Art. 33, unless the breach is unlikely to pose a risk to individuals' rights.
This is the only one of the UAE's three regimes where a specific notification window was confirmed by direct reading in this research pass; the federal PDPL defers its timeline to unconfirmed Executive Regulations, and the DIFC Law's own breach-notification timeline (Part 7) was not individually pulled.
What it requires →
Art. 9 requires the Controller to notify the Bureau of a breach that would prejudice the privacy, confidentiality, or security of personal data, at the time it becomes aware of the breach, within a period the Decree-Law itself defers to the Executive Regulations. No fixed number of hours or days is stated in the Decree-Law's own text; the timeline is not established pending the unconfirmed Executive Regulations (see the jurisdiction summary).
Data Subject notification is also required where the breach meets a threshold the Decree-Law's text does not fully set out in the provisions read.
Comprehensive regime
What it requires →
The ADGM Data Protection Regulations are the equivalent statute of the Abu Dhabi Global Market free zone (Abu Dhabi's Al Maryah and Al Reem Island financial free zone), enforced by ADGM's own Commissioner of Data Protection under ADGM's separate court system, and apply only within that free-zone footprint, not to a UAE business operating outside it.
This document cites the consolidated text as amended through February 2024; the exact original 2021 commencement date was not independently re-derived from primary text in this research pass, so 2021-02-14 is carried from the corpus's own record rather than independently confirmed. Section 1's Biometric Data definition names facial images and dactyloscopic data as worked examples, with the same adequacy-plus-alternative-safeguards cross-border transfer structure as the federal PDPL and DIFC Law. No source-based exclusion for a recording-derived biometric identifier was found.
cite DIFC Law No. 5 of 2020
stage IN FORCE in force since 2020-07-01
binds private bodies
source official consolidated statute text, published at assets.u.ae
What it requires →
The DIFC Data Protection Law is a separate statute of the Dubai International Financial Centre free zone, in force since 2020-07-01, enforced by the DIFC Commissioner of Data Protection, not the federal Bureau. It applies only within the DIFC's own geographic free-zone footprint (Dubai's financial district), not to a UAE business operating onshore elsewhere. Controller and Processor are General Data Protection Regulation (GDPR)-style defined roles (Sched. 1). Sched.
1's Special Categories of Personal Data includes "genetic data and biometric data where it is used for the purpose of uniquely identifying a natural person," with no source-based exclusion for an identifier derived from a recording, so processing such data ordinarily requires explicit consent or another qualifying condition.
The DIFC framework is close to full GDPR Chapter III parity on data-subject rights (portability at Art. 37, automated decision-making and profiling safeguards at Art. 38, non-discrimination at Art. 39, confirmed by the Law's own index), and Arts. 26-27 set a near-identical adequacy-plus-alternative-safeguards structure to the federal PDPL for cross-border transfer.
The individual operative texts of these articles, and of the Part 7 breach-notification provisions and any private-right-of-action provision, were not each pulled verbatim in this research pass; this document records the structure the index confirms rather than asserting undconfirmed detail.
What it requires →
The federal PDPL is the UAE's onshore comprehensive personal-data statute, applying outside the DIFC and ADGM free zones. Processing requires a lawful basis, most commonly the Data Subject's consent, with Art. 4 listing alternative grounds including a consent exception at Art. 4(2) for data the Data Subject has made public by their own act. Controller and Processor are General Data Protection Regulation (GDPR)-style defined roles, with the Controller determining purposes and means and bearing primary compliance duty.
Art. 1's Biometric Data definition names facial images and fingerprints as worked examples and lists Biometric Data as a category of Sensitive Personal Data, so an identity-linked voiceprint or faceprint ordinarily requires the Data Subject's explicit consent as its legal basis; no exclusion for an identifier derived from a photo, video, or audio recording was found.
The Decree-Law's Art. 28 Executive Regulations, which would supply operative detail including the breach-notification timeline, could not be confirmed to exist at primary source in this research pass; a corpus candidate citing "Cabinet Resolution No. 83 of 2022" as that Executive Regulation is confirmed wrong (that instrument is an unrelated vehicle speed-radar regulation), and is not authored here.
Cross border transfer
What it requires →
Art. 22 permits transfer of personal data outside the UAE to a jurisdiction the Bureau (the UAE Data Office) has approved as having an adequate data-protection law and enforcement authority. Where no such adequacy finding exists, Art. 23 permits transfer under a contract binding the foreign recipient to PDPL-equivalent standards, or with the Data Subject's explicit consent provided the transfer does not contradict UAE public or security interest.
No blanket data-localization requirement was found; transfer is conditioned on one of these bases rather than prohibited outright.
Enforcement supervision
What it requires →
The UAE Data Office ("the Bureau", established by Federal Decree-Law No. 44 of 2021) is the federal supervisory authority. A grievance against a Bureau decision goes to the Bureau itself first under Art. 25. Administrative penalty amounts are not set in the Decree-Law itself: Art. 26 requires a separate Council of Ministers decision, on the General Director's recommendation, to list violations and set administrative penalties.
No provision creating a private right of action for a Data Subject to sue a Controller directly was found in the articles read; this is recorded as not established rather than a confirmed absence, since the full Act was not read in its entirety.